Evaluating Temporal and Structural Anomaly Detection Paradigms for DDoS Traffic

📅 2026-04-17
📈 Citations: 0
Influential: 0
📄 PDF

career value

201K/year
🤖 AI Summary
This study addresses the common practice in existing DDoS detection methods of defaulting to either temporal or structural features without systematically evaluating their suitability for the underlying traffic characteristics. To overcome this limitation, the authors propose a lightweight, data-driven pre-selection framework that automatically identifies the more appropriate feature representation prior to model training. The framework leverages two diagnostic metrics—first-order lag autocorrelation and cumulative explained variance from PCA—to guide feature selection, resorting to hybrid features only when necessary. Experimental evaluation on two datasets with markedly different statistical properties demonstrates that structural features consistently match or outperform temporal features, with the performance gap widening significantly as temporal dependencies weaken. This approach avoids indiscriminate feature fusion, thereby enhancing both detection efficiency and model interpretability.

Technology Category

Application Category

📝 Abstract
Unsupervised anomaly detection is widely used to detect Distributed Denial-of-Service (DDoS) attacks in cloud-native 5G networks, yet most studies assume a fixed traffic representation, either temporal or structural, without validating which feature space best matches the data. We propose a lightweight decision framework that prioritizes temporal or structural features before training, using two diagnostics: lag-1 autocorrelation of an aggregated flow signal and PCA cumulative explained variance. When the probes are inconclusive, the framework reserves a hybrid option as a future fallback rather than an empirically validated branch. Experiments on two statistically distinct datasets with Isolation Forest, One-Class SVM, and KMeans show that structural features consistently match or outperform temporal ones, with the performance gap widening as temporal dependence weakens.
Problem

Research questions and friction points this paper is trying to address.

anomaly detection
DDoS traffic
temporal features
structural features
feature representation
Innovation

Methods, ideas, or system contributions that make the work stand out.

anomaly detection
feature selection
temporal vs structural features
unsupervised learning
DDoS detection
🔎 Similar Papers
No similar papers found.
Y
Yasmin Souza Lima
Institute of Exact and Technological Sciences, Federal University of Viçosa (UFV) – MG – Brazil
Rodrigo Moreira
Rodrigo Moreira
Federal University of Viçosa
IoTCloudNetworksRedesAI
L
Larissa F. Rodrigues Moreira
Institute of Exact and Technological Sciences, Federal University of Viçosa (UFV) – MG – Brazil
T
Tereza Cristina M. de B. Carvalho
University of São Paulo (USP), 05.508-010 – São Paulo – SP – Brazil
F
Flávio de Oliveira Silva
Department of Informatics – School of Engineering, University of Minho (UMinho) – Braga – Portugal